Associate Application Pentester
Rhino Security Labs Inc
Seattle, washington
Job Details
Full-time
Full Job Description
Description
Are you excited by exploiting web applications, and looking to do it professionally? Ready to turn that bug bounty or CTF experience into a full-time role? Do you want more than just to “get your foot in the door,” but have technical mentorship and growth as a new penetration tester?
Your excitement for pentesting has grown from an interest into a serious career goal, and you’ve learned a lot through self-study. A lot of technical areas interest you but you’re comfortable with – and excited about – webapp pentesting. You can exploit the OWASP Top 10, have hands-on experience with appsec labs (like the Web Security Academy), and Burpsuite Community is your go-to tool.
Finding new bugs is your passion, but you’re comfortable working with people too. Whether talking to pentesters or non-technical clients, you can communicate both ”in the technical weeds” as well as in higher-level language. You’re still learning a lot, but eager to be able to teach others in the future.
If this sounds like you, we’d like to chat. We have an amazing team of people at Rhino, and think you’ll love getting to know us.
What Rhino can do for you
- Provide an educational, supportive environment to start – and grow – your pentesting career
- Provide opportunity to learn from teammates in new technical areas, such as mobile app and API pentesting
- Ensure your voice is heard, influencing both technical and business strategies
What you can do for Rhino
- Learn from others, engage with the team, ask questions constantly
- Execute web application pentests (first with support and then independently), providing clients with remediation guidance for all identified vulnerabilities
- Grow your technical security skills, both in exploiting web and mobile apps and in other areas
Requirements
- Solid fundamentals in web application pentesting, with experience in OWASP Top 10, Burpsuite, and hands-on web pentesting labs; pentesting experience in mobile apps (iOS/Android) or APIs a bonus
- Solid understanding of common webapp vulnerabilities, exploitation techniques, and remediation options
- Hands-on experience scripting with Python, building and expanding on pentesting tools
- Passion for learning new technologies and processes, and contributing to refining existing capabilities
Benefits
- Full Health Benefits - fully covered Medical / Dental / Vision
- Quarterly bonuses, totaling 5-15% salary annually
- 401k w/Matching
- Annual Training and Research stipend of $2,500 for all pentesters
- Regular Research and Development opportunities (with bonus structure for all published research)
- 3 weeks of Paid Time Off (in addition to 9 paid Holidays)
- Company retreats (Defcon!) and team-building activities, both remote and in-person